Organizational backing, a matching repository, and a clear Apache-2.0 license support dependable use. Maintenance is concentrated in one contributor, and the repository has no security policy or scanning tools.
82%
Total Score
88
100
89
88
One contributor made all 35 commits in the last 3 months, giving the repository a top-contributor share of 100%. Organizational ownership partly mitigates handoff risk, but the concentrated activity remains a maintenance caution.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so these low counts modestly limit external validation but do not outweigh the active release and commit history.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap, not evidence of unsafe code by itself.
The repository has no SECURITY.md or other declared security policy. This makes vulnerability reporting and response expectations less clear for a package intended for application integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tencentcloud/common Version >=3.0.1673 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.